Skip to content
ScopefileGet the app

Module 19Domain 8 of 9Cloud Computing

Cloud computing security: models, containers, serverless

Cloud computing security in CEH Module 19 starts from one question: which layer is yours and which is the provider's. From there the module moves through containers, serverless functions, exposed storage and the identity mistakes that turn a small bug into a large breach.

Exam
312-50
Domain
8 of 9
Domain weight
5%
This file
~5%
Targets
17

Cloud against the rest of the blueprint

What to learn first, and what to skip

Start with the NIST definition, because the CEH's cloud vocabulary follows it: five essential characteristics (on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service), three service models and four deployment models (NIST SP 800-145). Add multi-cloud as a variant of hybrid, and fog and edge computing as processing moved closer to the devices that produce the data.

Then shared responsibility. The provider always secures the facility and the physical hardware. You always own your data, your identities and how access is configured. Everything between those two lines moves with the service model, so decide which layer a failure sits in before you decide whose failure it is.

Deployment models take one sentence each. Public cloud is shared infrastructure sold to anyone; private cloud serves one organization; community cloud serves a group with shared requirements, such as agencies under the same regulation; hybrid joins two or more of them so workloads can move between them.

Skip provider console menus. The v13 outline names AWS, Azure and GCP, so learn to read a short policy or configuration excerpt; where a setting lives in a web console is not worth an evening.

Three ways to run code

Virtual machines, containers and serverless functions from the security side
PointVirtual machineContainerServerless function
You manage (differs)Guest OS and everything above itImage, app and its dependenciesFunction code and its permissions
Isolation boundary (differs)HypervisorShared host kernelProvider-managed runtime
Typical lifetime (differs)Long-runningMinutes to monthsOne event
Signature attack (differs)Escape from guest to hypervisorEscape from container to hostEvent injection through untrusted input
Where secrets leak (differs)Disk images and snapshotsImage layers and registriesEnvironment variables and broad roles

Tinted rows marked ≠: at least one of the 3 differs from the others.

Kubernetes adds an orchestration layer on top of containers; an exposed API server or dashboard is a high-value target of its own.

Containers and serverless from the defender's side

Container security starts before anything runs. Build from minimal base images, scan them for known vulnerabilities, pull only from a registry you control, and run processes as an unprivileged user. Keep the host kernel patched: every container on that host shares it, so one kernel flaw is everyone's flaw.

Kubernetes adds its own controls. Role-based access control decides what a stolen service account token can do, and admission policies stop privileged or unscanned workloads from being scheduled at all.

Serverless moves the work to permissions and input. Give each function only the role its job needs, and treat every event source, whether a queue message, an uploaded file or an HTTP call, as untrusted input. There is no server for you to patch, but the code and its dependencies are still yours.

Cloud attack names to recognize

Open storage
Buckets or blobs readable by anyone. A customer-side misconfiguration; the provider's platform was never breached.
Man-in-the-cloud
Theft of a file-sync token, which lets the attacker sync the victim's files without ever knowing the password.
Cryptojacking
Stolen credentials or compute used to mine cryptocurrency. The first sign is often the invoice.
Cloudborne
An implant in bare-metal server firmware that survives when the hardware is handed to the next customer.
Metadata endpoint
An internal-only address on each cloud instance that serves its configuration. Keeping it unreachable from user-supplied requests is a classic server-side request forgery defense; the XSS vs CSRF vs SSRF comparison covers the bug itself.

Drill the cloud module

These run from service models to incident calls. Commit to an answer before opening the notes, then read the note on the option you rejected last.

Answered 0/17Hits 0

T-01

A publicly invokable serverless function with broad IAM permissions shows a sudden spike in invocation rate and increasing execution errors over the past hour. What are the two most critical immediate containment actions?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AArchiving logs and metrics matters for the investigation, but on its own it does nothing to stop the abuse that is happening right now.
  2. BRotating credentials is an important follow-up once you suspect exposure, but it does not stop the public endpoint from being invoked in the meantime.
  3. CFlow logs and IP blocks are weak containment for a public serverless function, whose callers rotate addresses easily and do not traverse a VPC you control.
  4. DCorrect: removing public invoke permission cuts off the attacker's entry point, and preserving logs and telemetry keeps the evidence needed to scope what happened.
T-02

A client authorizes a penetration test and requests that you include their cloud service provider in the assessment scope. Which action is legally required before proceeding?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: the provider owns the underlying infrastructure, so testing it requires the provider's own written authorization; the client cannot grant permission over assets it does not own.
  2. BAn indemnification agreement shifts liability between you and the client, but it does not give you legal authority to test a third party's systems.
  3. CLaw enforcement is not notified before a routine authorized test; authorization comes from the asset owners, not from police.
  4. DRestricting the test to passive OSINT sidesteps the issue rather than satisfying it, and it does not meet the client's request to assess the provider.
T-03

Which cloud service model places the most security responsibility on the customer?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AIn SaaS the provider runs the application, platform and infrastructure, so the customer mainly manages its data, users and access settings.
  2. BIn PaaS the provider manages the operating system and runtime, leaving the customer responsible for its application code, data and configuration.
  3. CIn FaaS the provider handles servers, scaling and runtime patching, so the customer secures only function code, permissions and data.
  4. DCorrect: in IaaS the customer manages the operating system, middleware, applications, network configuration and data, carrying the largest share of the shared responsibility model.
T-04

A company hosts marketing images in an Azure Storage account that also contains customer financial records. Marketing images must remain publicly accessible while financial records require strict access control. Which solution BEST preserves public access to images while protecting sensitive data?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AMaking the whole container public exposes the financial records to anyone; versioning only keeps old copies and does not restrict access.
  2. BA URL-pattern proxy adds a fragile extra layer, and the records remain exposed if anyone reaches the storage endpoint directly or a pattern rule is wrong.
  3. CCorrect: separating data by sensitivity lets the image container stay public while the private container is reached only with scoped, time-limited SAS tokens.
  4. DEncryption keys protect data at rest, but if the container ACL still allows public reads, the storage service will decrypt and serve the records to anyone.
T-05

What is data remanence in the context of cloud computing security?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: data remanence is the residual data left on disks or memory after deletion, a concern in the cloud because hardware is reused across tenants.
  2. BChecking integrity with hashes detects modification of data; it has nothing to do with leftover data after deletion.
  3. CEncrypting data during migration protects it in transit, which is a different control from the leftover-data problem that remanence describes.
  4. DStoring copies across regions is replication for availability and disaster recovery, not residual data left behind after deletion.
T-06

Which of the following is a primary security concern when multiple virtual machines share the same physical hardware?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APatching guest operating systems is always required, but it is not the concern created specifically by sharing physical hardware.
  2. BPower consumption is an operational cost issue for the data center, not a security risk between co-located virtual machines.
  3. CCorrect: co-tenant VMs compete for CPU, memory and cache, and weak isolation enables side-channel attacks, noisy-neighbor denial of service or VM escape.
  4. DBandwidth limits affect performance, but they are not the primary security concern raised by multiple tenants on one physical host.
T-07

A sensitive IAM role must be assumable only by approved service accounts with MFA, during business hours, from corporate IP ranges. Which trust policy conditions accomplish this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AThis covers network location but has no MFA condition, and a token issue-time window is not the same as restricting assumption to business hours.
  2. BCorrect: these three condition keys together enforce MFA, approved source networks and a time window, matching each requirement in the stem.
  3. CSecureTransport only requires HTTPS and adds nothing about MFA or business hours, so two of the three requirements are missing.
  4. DUser-agent strings are trivially spoofed and a region restriction is irrelevant here, and the set still lacks any time-of-day condition.
T-08

In a cloud computing environment, which of the following processes determines the specific data and services a user can interact with after proving their identity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAuthentication proves who the user is; it comes first and does not by itself decide what the user may access.
  2. BCorrect: authorization decides which data and services an already authenticated identity may use, typically through roles, policies or permissions.
  3. CData management covers how data is stored, classified and maintained, not the per-user decision about what an identity may access.
  4. DAn SLA is a contract defining service levels such as uptime between provider and customer, not an access-control process.
T-09

What type of attack involves creating a malicious VM image and publishing it to a cloud marketplace?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADNS amplification is a reflection-based denial-of-service technique using open resolvers, unrelated to publishing images in a marketplace.
  2. BRoute table poisoning manipulates routing entries to redirect traffic, not to distribute backdoored machine images.
  3. CSession riding is another name for cross-site request forgery, which abuses a logged-in user's browser rather than a marketplace image.
  4. DCorrect: a malicious VM image attack plants a backdoored or vulnerable image in a marketplace so that anyone who launches it deploys the attacker's code.
T-10

During a cloud security assessment, an analyst identifies a low-severity server-side request forgery (SSRF) vulnerability. Under which circumstance would this finding pose a critical risk to the entire organization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAn unpatched legacy OS raises local risk, but it does not explain how one SSRF would reach across the whole organization.
  2. BRunning without load balancers is an availability design choice and does not amplify what an SSRF can reach or steal.
  3. CCorrect: if SSRF can reach the metadata service and obtain credentials of a role with cross-account admin rights, a minor bug becomes organization-wide compromise.
  4. DDeprecated crypto libraries are a separate weakness and do not change the blast radius of the request-forgery flaw itself.
T-11

What security mechanism is used to ensure that data stored in the cloud remains protected even when the cloud provider has physical access to the storage media?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: encrypting stored data, ideally with keys the customer controls, keeps disks unreadable even to someone with physical access to the provider's hardware.
  2. BMFA protects logins to accounts and consoles, but it does nothing for data read directly from the physical storage media.
  3. CIntrusion detection alerts on suspicious activity; it neither prevents nor protects against reading data straight off a disk.
  4. DNetwork segmentation limits traffic paths between systems, which is irrelevant once someone has the physical media in hand.
T-12

An incident responder detects active exploitation of a vulnerable web application deployed on a cloud virtual machine. The attacker is attempting to exfiltrate sensitive data. What should be the responder's immediate priority?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AFixing deployment manifests prevents future instances from repeating the flaw, but it does nothing to stop the exfiltration happening now.
  2. BCorrect: containment comes first, so cutting public access and isolating the instance stops the data loss while keeping it available for investigation.
  3. CPatching is eradication, which follows containment; patching a host an attacker still controls may not remove their foothold or stop the transfer.
  4. DMemory capture preserves evidence and is valuable, but doing it before containment lets the exfiltration continue during the dump.
T-13

Which strategy should an organization adopt to ensure that their cloud service providers are adhering to cybersecurity best practices?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: regular audits, assessments and review of attestation reports give ongoing evidence that the provider meets agreed security controls.
  2. BBond assurance is not an established cybersecurity practice and provides no visibility into how the provider actually operates.
  3. CBanning cloud providers abandons the business need rather than managing provider risk, so it is not a realistic strategy.
  4. DThere is no recognized pentuple-factor authentication standard, and authentication strength says nothing about the provider's broader practices.
T-14

What is a key security advantage of containers compared to traditional virtual machines?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AContainers do not encrypt anything by default; encryption has to be configured separately for storage and traffic.
  2. BVulnerability scanning of container images is a separate tool in the pipeline, not a built-in property of containers.
  3. CCorrect: a minimal container image ships only what the application needs, so there are fewer packages and services for an attacker to target.
  4. DContainers share the host kernel, so their isolation is weaker than a VM's; a kernel flaw can enable container escape.
T-15

Chris has noticed suspicious activity within their organization’s cloud-hosted database and aims to prevent data breaches. Which security measure should be prioritized to limit the attacker's ability to move laterally within the system?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: segmenting the network confines a compromised component so the attacker cannot freely reach other systems from the database tier.
  2. BMFA makes stealing or reusing credentials harder, but it does little against an attacker already moving between internal systems.
  3. CEncryption protects data confidentiality, but it does not restrict which hosts a foothold can reach next.
  4. DBackups support recovery after loss or ransomware; they do not slow an attacker's movement across the environment.
T-16

Which of the following is COMMONLY used by a cloud service provider to verify the identity of a user accessing their services?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AFirewalls filter network traffic by rules; they do not verify who a user is.
  2. BA VPN creates an encrypted tunnel; it may require login, but its purpose is protecting the connection, not proving identity.
  3. CSSO lets one authentication grant access to many services, a convenience layer that relies on a separate identity check rather than strengthening it.
  4. DCorrect: MFA verifies identity by requiring two or more independent factors, such as a password plus a one-time code or hardware key.
T-17

Your company needs a service that allows you to develop, test, and manage applications without handling the underlying infrastructure. Which cloud service model should you choose?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHardware-as-a-Service means renting physical equipment, which still leaves you managing that infrastructure.
  2. BCorrect: PaaS provides a managed runtime, tooling and infrastructure so teams can build, test and deploy applications without administering servers.
  3. CIaaS hands you virtual machines, storage and networks to manage yourself, the opposite of avoiding infrastructure work.
  4. DSaaS delivers a finished application for end users, not a platform for developing and managing your own applications.

Cloud module, briefly

Why is Kubernetes a risk of its own?

Kubernetes runs the containers for you, so it holds the keys to all of them: its API server schedules workloads and stores secrets, and its dashboards can start or stop anything. Protect it as a management plane, with role-based access control and no anonymous access.

Which cloud facts deserve flashcards?

The five NIST characteristics, the three service models, the four deployment models, and the names of container and serverless attack types. The rest is reasoning you build on the targets.

Where does cryptography meet cloud security?

Through key management: who holds the keys and whether a key left in code exposes everything it can decrypt. The algorithms themselves belong to the cryptography module, the last file in blueprint order.

Sources